• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

D385 Software Security And Testing - Questions With Complete Solutions

Document preview thumbnail
Preview 3 out of 24 pages

D385 Software Security And Testing - Questions With Complete Solutions

Content preview

D385 Software Security And Testing - Questions With
Complete Solutions

In the context of outbound log messages, sanitizing is the practice of
reviewing and modifying log data to remove sensitive or confidential
information, validate its correctness, and ensure that it adheres to security
and privacy standards before it's shared with external systems or users.

How to spot -
Log Injection Correct Answer - - Look for Unsanitized User Input
- Examine Log Functions
- Check for User-Controlled Data

Defensive Programming Correct Answer - a software development
approach that aims to create robust and secure software by anticipating and
guarding against unexpected failures and security vulnerabilities.

It involves implementing error handling, input validation, and security
measures to protect the software from unexpected inputs, attacks, or faults,
thereby enhancing its reliability and security.

Static Testing Correct Answer - a type of software testing that examines
the source code, design, or documentation without executing the program. It
aims to identify defects early in the development process.

white box

Dynamic Testing Correct Answer - a software testing technique that
involves executing the program or application with test cases to observe its
behavior at runtime. It aims to find defects related to functionality,
performance, and reliability

white-box, black-box, grey-box

Fuzz Testing (Fuzzy Testing) Correct Answer - a testing technique that
involves providing unexpected or random inputs to a software application to

,discover vulnerabilities, crashes, or unexpected behavior. It is commonly used
for security testing

black-box

Unit Testing Correct Answer - a level of software testing where smallest
individual components - units of a software application are tested in isolation
to ensure they work as intended. It helps identify and fix issues at the smallest
functional level.

white box

frequency: as soon as an unit is complete, before it moves on

advantages: done early, easier to find root cause

disadvantages: tunnel vision since performed the developer, less formal

Integration Testing Correct Answer - a level of software testing that
focuses on testing the interactions between different units or modules of a
software application. It ensures that the integrated components work
together correctly

grey box

frequency: usually when 2 or more units get integrated, team specific
guidelines, done by developers or specialized teams

advantages: more formal, manual /tools

patterns:
- client /server integration
- collaboration integration (mars probe metric vs us)
- distributed services integration
- layer integration

Regression Testing Correct Answer - Regression testing is a type of testing
performed to verify that recent code changes or updates do not introduce new

, defects or negatively impact existing functionality. It typically involves re-
running previous test cases.

grey-box or black-box

frequency: when a change is made, to verify that the change didn't reintroduce
problems, testing team

disadvantages: could be implemented poorly (radiation 8 ppl died)

Patterns:
- regress all
- regress some

User Acceptance Testing (UAT) Correct Answer - a phase of software
testing where end users or clients test the software to ensure it meets their
requirements and is ready for production use. It validates that the software
aligns with user expectations.

black-box (because it focuses on whether the software meets user
requirements without diving into internal code).

frequency: alpha, beta, done by end users, subject matter expert

disadvantages: end users may be untrained, lack of focus, bias

Penetration Testing Correct Answer - a type of security testing where
ethical hackers attempt to exploit vulnerabilities in a software system to
assess its security posture. The goal is to identify weaknesses before malicious
actors can exploit them.

could be white-box, black-box or grey-box

ad hog (in testing) Correct Answer - someone to bang around the software
hoping to find problems, bad way

attack surface Correct Answer - The sum of all entry points through which
a system can be attacked

Document information

Uploaded on
April 16, 2025
Number of pages
24
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$22.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
StudyHall
3.8
(231)
Sold
1349
Followers
825
Items
17224
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions